What is CVE-2026-28178?
This vulnerability allows Contributor-level Cross Site Scripting (XSS) attacks in the Powerkit plugin. It affects Powerkit versions 3.1.0 and below. Users are advised to update the plugin to the latest version.
Azərbaycanca: Bu zəiflik Powerkit plaginində Contributor səviyyəli istifadəçilər tərəfindən Cross Site Scripting (XSS) hücumlarına imkan verir. Powerkit-in 3.1.0 və daha əvvəlki versiyalarına təsir edir. İstifadəçilərə plaqini ən son versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Powerkit plugin are vulnerable to CVE-2026-28178?
This XSS vulnerability affects Powerkit versions 3.1.0 and below.
What user level can exploit the CVE-2026-28178 vulnerability?
This vulnerability allows Contributor-level users to perform Cross Site Scripting (XSS) attacks.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.